<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>Web Application Security Forum - SPAM</title>
        <description>Ways to stop spam, detect robotic activity, and actually harm the spam trade, as well as how it works, how to circumvent filters, etc.</description>
        <link>http://sla.ckers.org/forum/list.php?9</link>
        <lastBuildDate>Sun, 19 May 2013 10:36:25 -0500</lastBuildDate>
        <generator>Phorum 5.2.15a</generator>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?9,51508,51508#msg-51508</guid>
            <title>Found some spammer files on my web server (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?9,51508,51508#msg-51508</link>
            <description><![CDATA[I've been getting some failed mail delivery reports at my catch-all email address on my server. Finding this weird, I had a feeling there was spam coming out of it.<br />
<br />
Connecting through FTP, I found some definitely odd files.<br />
<br />
1. A file violin.php which let the spammers send mail out of my server and domain through POST parameters.<br />
<br />
2. Three obscure, randomly named html files which were empty except for small obfuscated javascript that redirected to spam/adult websites and pop ups.<br />
<br />
3. One file in cgi-bin, &quot;mhstchk.cgi&quot; which seems to be the first file they put on the server. It seems to gather information about the server in order for them to decide whether it'll work for their spammer needs. Here's a few lines from the beginning:<br />
<br />
my $smtp = 'smtp.yandex.ru';<br />
<br />
	my $dns = '194.173.175.100';<br />
<br />
<br />
<br />
	my $fpart = &quot;hello_my_little_friend._You_have_download_this_page_and_see_this_source.&quot;;<br />
<br />
	my $lpart = &quot;_We_do_not_delete_anything_only_upload_change_your_passwords_and_do_not_say_it_to_anybody&quot;;<br />
<br />
<br />
And then it goes on to print &quot;uname -a&quot;, test Perl modules, the SMTP server, some DNS tests, etc.<br />
<br />
<br />
Now I'm wondering how they got the files on the server. Exploit of apache? Do I need to tell my hosting company to check for cracks in this shared server? Brute forcing my PHP password? Exploit in wordpress?<br />
<br />
Anyone see this before?<br />
<br />
EDIT: Just found them in my FTP access logs. So did they just brute force my password? It seems there were more files they put in my cgi folder that they since deleted. Also it seems that cgi file was there for a long time.]]></description>
            <dc:creator>Royal2000H</dc:creator>
            <category>SPAM</category>
            <pubDate>Tue, 02 Oct 2012 17:05:54 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?9,35861,35861#msg-35861</guid>
            <title>sending spoof e-mail understanding the dynamic (2 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?9,35861,35861#msg-35861</link>
            <description><![CDATA[hey guys this is what i want to do:-(consider me as newbie to entire spoofing / spamming game)<br />
<br />
i'm not at user of site abc.com but what i plan to do is to use the admin mail of abc website (e.g admin@abc.com) and sent a spoof email to person zyz@abc of the same domain.<br />
<br />
I want to do this with lowest level of detection possible. Do i have to do an open-relay thing? if yes would it not be detected by mail-server anti-spoofing / black-list filters. How could i avoid my mail ending up at the spam box of my victim machine? if it does well spams gets deleted and bad things happen to it<br />
<br />
If there is an command line tool for crafting fake email how could these cli tools provision the user of formatting (e.g insert hyper-link behind text) inserting images/ header and footer. The reason im saying this is coz without such dynamic content it would be impossible in my case to lure the potential victim. I cannot add the url if it has xss signatures in command line it would be so easy to detect?right....<br />
<br />
Thank you for reading my message.Please help me find the right path:)<br />
<br />
appreciate...]]></description>
            <dc:creator>lazer</dc:creator>
            <category>SPAM</category>
            <pubDate>Thu, 20 Jan 2011 16:56:48 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?9,35616,35616#msg-35616</guid>
            <title>How do I deal with this sort of hacker/spammer? (1 reply)</title>
            <link>http://sla.ckers.org/forum/read.php?9,35616,35616#msg-35616</link>
            <description><![CDATA[Some &quot;usermane&quot; is requesting a &quot;username&quot; in my wordpress blog.<br />
<br />
<br />
I did not expect this to happen with my wordpress blog.  I do not know if it is just users stupidity or if it is spammers trying to break into my blog.  Either way, it is something that needs fixing.  Apparently people are trying to log in without registering.<br />
<br />
<br />
I have been getting annoying email messages that say essentially:<br />
<blockquote class="bbcode"><div><small>Quote<br/></small><strong></strong><br/>
	SoAndSo (SomeEmail@somewhere.com) has requested a username at MyWebForumAndBlog<br />
<br />
	h t t p : / / w w w . M y S i t e . c o m<br />
<br />
	To approve or deny this user access to MyWebForumAndBlog go to...</div></blockquote>
<br />
<br />
That is not exactly what it says, but you get the idea.  Click <a href="http://i67.photobucket.com/albums/h292/Athono/WordPress/ugh_0.jpg" rel="nofollow" >here</a> to see an actual message.<br />
<br />
<br />
So I am guessing that what is happening is that someone just clicks on &quot;log in&quot; and then requests a password instead of clicking on Register.  But there are so many of these messages that I have to wonder if this is a spam bot.<br />
<br />
<br />
On the other hand, the message says it is requesting a username, not a password.  So this is some sort of wordpress spam and trick someone is using where they are bypassing the normal login.<br />
<br />
<br />
And it does not make sense.  Think of it.  Some &quot;usermane&quot; is requesting a &quot;username&quot;.  How do they do that?]]></description>
            <dc:creator>Captain Xarzu of Alpha Centauri</dc:creator>
            <category>SPAM</category>
            <pubDate>Mon, 06 Sep 2010 15:32:05 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?9,31755,31755#msg-31755</guid>
            <title>Which Domain Extension best (2 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?9,31755,31755#msg-31755</link>
            <description><![CDATA[I want the solution which is the Best extension to register the Website Domain ..I found the Domain name registration site named as seo://www.tucktail.com/   I want register there my business site's  Domain name Which is best extension .ORG or .COM help me please.]]></description>
            <dc:creator>reshmaa</dc:creator>
            <category>SPAM</category>
            <pubDate>Thu, 08 Oct 2009 20:18:48 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?9,26806,26806#msg-26806</guid>
            <title>Phishing with Non Scriptable User Input (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?9,26806,26806#msg-26806</link>
            <description><![CDATA[Some thoughts here http://securethoughts.com/2009/03/phishing-with-non-scriptable-user-input/. You can use this for spams.]]></description>
            <dc:creator>Inferno</dc:creator>
            <category>SPAM</category>
            <pubDate>Mon, 02 Mar 2009 00:05:10 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?9,24729,24729#msg-24729</guid>
            <title>Only totally free hosting service. (6 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?9,24729,24729#msg-24729</link>
            <description><![CDATA[Free cPanel Web Hosting with PHP5/Mysql - no advertising!<br />
Register now: http://deleted.stupid.link<br />
<br />
We can offer you a free web hosting package packed with advanced features for hosting &amp; building professional dynamic websites. We provide secure free web space with all the web hosting tools you could possibly ever need.<br />
<br />
Our package includes:<br />
- 350 MB of Disk Space, 100 GB Bandwidth<br />
- Host your own domain (http://www.yourdomain.com)<br />
- cPanel Powered Hosting (you will love it)<br />
- Over 500 website templates ready to download<br />
- Easy to use website builder<br />
- Free POP3 Email Box with Webmail access<br />
- FTP and Web based File Manager<br />
- PHP, MySQL, Perl, CGI, Ruby.<br />
- And many more..<br />
<br />
Click here to visit us: http://deleted.stupid.link<br />
<br />
_____________________________________________________________________<br />
PERSONAL / CEAP HOSTING  Starts at $3.00/mo Register here  https://another.stupid.link.deleted]]></description>
            <dc:creator>Anonymous User</dc:creator>
            <category>SPAM</category>
            <pubDate>Wed, 08 Oct 2008 11:51:03 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?9,23573,23573#msg-23573</guid>
            <title>Manual Spamming Blogs (10 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?9,23573,23573#msg-23573</link>
            <description><![CDATA[Okay, this is my new favorite thing to hate:<br />
<br />
83.26.205.84 - - [18/Jul/2008:05:48:06 -0500] &quot;GET /blog/20070725/res-timing-attack/ HTTP/1.1&quot; 200 14430 &quot;http://www.google.com/search?hl=en&amp;client=firefox-a&amp;channel=s&amp;rls=org.mozilla:pl:official&amp;q=%22leave+a+reply%22&amp;start=80&amp;sa=N&quot; &quot;Mozilla/5.0 (Windows; U; Windows NT 6.0; pl; rv:1.8.1.14) Gecko/20080404 Firefox/2.0.0.14&quot;<br />
<br />
The part that's stupid about this is that it's manual.  The person really is a real person, but instead of writing a robot like any normal person they are manually writing their comments.  I've since changed some of the text on the page to make ha.ckers.org stop showing up in default text search queries like this, but still.  So annoying!]]></description>
            <dc:creator>rsnake</dc:creator>
            <category>SPAM</category>
            <pubDate>Fri, 17 Oct 2008 14:18:51 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?9,21719,21719#msg-21719</guid>
            <title>New Spam Technique? (9 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?9,21719,21719#msg-21719</link>
            <description><![CDATA[Do you know new spammer techniques that is being used now a days? hope you can share them with me since I'm doing a simple research about it.<br />
<br />
Thanks]]></description>
            <dc:creator>inzomiac</dc:creator>
            <category>SPAM</category>
            <pubDate>Thu, 03 Apr 2008 17:42:31 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?9,21708,21708#msg-21708</guid>
            <title>php mailer sender ID test (3 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?9,21708,21708#msg-21708</link>
            <description><![CDATA[Just experimenting with a php mailer I uploaded and I sent a message to my hotmail address with a from address of my choice. It went straight to junk and failed the sender ID test and was marked as &quot;potentially dangerous&quot;, even though I just put &quot;test&quot; as subject and message body.Is it possible to get past this,and is it only possible with a massmailer? If so, what smtp server should I use, as all the previous ones I've used with a mailer program keep giving errors.]]></description>
            <dc:creator>shad0w7</dc:creator>
            <category>SPAM</category>
            <pubDate>Thu, 24 Dec 2009 17:53:56 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?9,20868,20868#msg-20868</guid>
            <title>Dear google (4 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?9,20868,20868#msg-20868</link>
            <description><![CDATA[Yes, we know you hate us and all...but please don't run mail servers if you can't set them up properly.<br />
<br />
<pre class="bbcode">
Feb 23 00:00:20 mail postfix/smtpd[39402]: NOQUEUE: reject: RCPT from an-out-0708.google.com[209.85.132.250]: 550 5.1.1 &lt;RosannacalculableMeans@ck
ers.org&gt;: Recipient address rejected: User unknown in virtual mailbox table; from=&lt;&gt; to=&lt;RosannacalculableMeans@ckers.org&gt; proto=ESMTP helo=&lt;an-ou
t-0708.google.com&gt;
Feb 23 00:00:45 mail postfix/smtpd[39403]: NOQUEUE: reject: RCPT from wr-out-0506.google.com[64.233.184.226]: 550 5.1.1 &lt;ErnablowbackKruse@ckers.o
rg&gt;: Recipient address rejected: User unknown in virtual mailbox table; from=&lt;&gt; to=&lt;ErnablowbackKruse@ckers.org&gt; proto=ESMTP helo=&lt;wr-out-0506.goo
gle.com&gt;
Feb 23 00:01:05 mail postfix/smtpd[38117]: NOQUEUE: reject: RCPT from ug-out-1314.google.com[66.249.92.171]: 550 5.1.1 &lt;HeathereulogyCrowley@ckers
.org&gt;: Recipient address rejected: User unknown in virtual mailbox table; from=&lt;&gt; to=&lt;HeathereulogyCrowley@ckers.org&gt; proto=ESMTP helo=&lt;ug-out-131
4.google.com&gt;
Feb 23 00:02:08 mail postfix/smtpd[39402]: NOQUEUE: reject: RCPT from hs-out-0708.google.com[64.233.178.240]: 550 5.1.1 &lt;JulietjohnstonSchulz@cker
s.org&gt;: Recipient address rejected: User unknown in virtual mailbox table; from=&lt;&gt; to=&lt;JulietjohnstonSchulz@ckers.org&gt; proto=ESMTP helo=&lt;hs-out-07
08.google.com&gt;
Feb 23 00:02:16 mail postfix/smtpd[38115]: NOQUEUE: reject: RCPT from ug-out-1314.google.com[66.249.92.169]: 550 5.1.1 &lt;CatherinesuitorCrowley@cke
rs.org&gt;: Recipient address rejected: User unknown in virtual mailbox table; from=&lt;&gt; to=&lt;CatherinesuitorCrowley@ckers.org&gt; proto=ESMTP helo=&lt;ug-out
-1314.google.com&gt;
Feb 23 00:02:25 mail postfix/smtpd[39403]: NOQUEUE: reject: RCPT from fg-out-1718.google.com[72.14.220.154]: 550 5.1.1 &lt;AntonechosenPuckett@ckers.
org&gt;: Recipient address rejected: User unknown in virtual mailbox table; from=&lt;&gt; to=&lt;AntonechosenPuckett@ckers.org&gt; proto=ESMTP helo=&lt;fg-out-1718.
google.com&gt;
Feb 23 00:02:31 mail postfix/smtpd[38815]: NOQUEUE: reject: RCPT from py-out-1112.google.com[64.233.166.182]: 550 5.1.1 &lt;AntondeferredWoody@ckers.
org&gt;: Recipient address rejected: User unknown in virtual mailbox table; from=&lt;&gt; to=&lt;AntondeferredWoody@ckers.org&gt; proto=ESMTP helo=&lt;py-out-1112.g
oogle.com&gt;
Feb 23 00:02:54 mail postfix/smtpd[38115]: NOQUEUE: reject: RCPT from ug-out-1314.google.com[66.249.92.172]: 550 5.1.1 &lt;RosannablowbackAlfaro@cker
s.org&gt;: Recipient address rejected: User unknown in virtual mailbox table; from=&lt;&gt; to=&lt;RosannablowbackAlfaro@ckers.org&gt; proto=ESMTP helo=&lt;ug-out-1
314.google.com&gt;
Feb 23 00:03:30 mail postfix/smtpd[38115]: NOQUEUE: reject: RCPT from hs-out-0708.google.com[64.233.178.241]: 550 5.1.1 &lt;QueencoloradoSkaggs@ckers
.org&gt;: Recipient address rejected: User unknown in virtual mailbox table; from=&lt;&gt; to=&lt;QueencoloradoSkaggs@ckers.org&gt; proto=ESMTP helo=&lt;hs-out-0708
.google.com&gt;
Feb 23 00:03:51 mail postfix/smtpd[38115]: NOQUEUE: reject: RCPT from py-out-1112.google.com[64.233.166.181]: 550 5.1.1 &lt;LeliasuperlunaryShipman@c
kers.org&gt;: Recipient address rejected: User unknown in virtual mailbox table; from=&lt;&gt; to=&lt;LeliasuperlunaryShipman@ckers.org&gt; proto=ESMTP helo=&lt;py-
out-1112.google.com&gt;
</pre>]]></description>
            <dc:creator>id</dc:creator>
            <category>SPAM</category>
            <pubDate>Sat, 01 Mar 2008 17:22:57 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?9,17644,17644#msg-17644</guid>
            <title>Log Spam (5 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?9,17644,17644#msg-17644</link>
            <description><![CDATA[Any ideas on how to hide referer these days since most logs (Google analytics/Statscounter) are done using Javascript?!<br />
<br />
I miss the good old days when we didn't depend on javascript and a simple fake HTTP HEADER injection would do the trick! (referer &amp; host)<br />
<br />
Also, is there anyone out there who have been sucessfuly spaming links on urchin.js? I am asking this because I have seen this week, for the fisrt time ever, the first log spam links on my statscounter acount!]]></description>
            <dc:creator>klaus</dc:creator>
            <category>SPAM</category>
            <pubDate>Mon, 18 Feb 2008 04:26:08 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?9,16448,16448#msg-16448</guid>
            <title>Rent a botnet (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?9,16448,16448#msg-16448</link>
            <description><![CDATA[I want to know where a botnet is rent.<br />
Could someone who knows a way to rent a botnet tell me the way?]]></description>
            <dc:creator>kaito834</dc:creator>
            <category>SPAM</category>
            <pubDate>Tue, 02 Oct 2007 11:52:17 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?9,15426,15426#msg-15426</guid>
            <title>How much is an email worth? (7 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?9,15426,15426#msg-15426</link>
            <description><![CDATA[How much would an average spammer pay for, say, 1000 unique emails? I'm curious because I heard at one time email grabbers were making several dollars a second.]]></description>
            <dc:creator>barbarianbob</dc:creator>
            <category>SPAM</category>
            <pubDate>Tue, 26 Jan 2010 03:26:13 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?9,14494,14494#msg-14494</guid>
            <title>Gmail marking legit emails as spam (13 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?9,14494,14494#msg-14494</link>
            <description><![CDATA[I run a legit website, A few months ago I could use php mail() function to send veritification emails to prevent spam but now GMAIL is marking my emails as SPAM.<br />
<br />
<br />
What can I do to resolve this issue?<br />
Did you blacklist us, if so why?<br />
Is it because our server is from Germany?<br />
Is there a work around? <br />
How can I view their blacklist?<br />
<br />
Anyhelp be great guys.]]></description>
            <dc:creator>ash</dc:creator>
            <category>SPAM</category>
            <pubDate>Tue, 11 Dec 2007 13:13:39 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?9,14421,14421#msg-14421</guid>
            <title>Second Life (1 reply)</title>
            <link>http://sla.ckers.org/forum/read.php?9,14421,14421#msg-14421</link>
            <description><![CDATA[With so many Second Life cheats, bots and hacks available lately, what's your view on SL Spamming? Any experiences to share?]]></description>
            <dc:creator>klaus</dc:creator>
            <category>SPAM</category>
            <pubDate>Mon, 10 Dec 2007 09:08:41 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?9,13899,13899#msg-13899</guid>
            <title>Fast-Flux Service Networks (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?9,13899,13899#msg-13899</link>
            <description><![CDATA[Lance Spitzner just posted this as a &quot;Know Your Enemy&quot; series from the HoneyNet Project on Fast-Flux Service Networks, which are used for building resilient botnets that are useful for sending spam:<br />
<br />
http://www.honeynet.org/papers/ff/fast-flux.html<br />
<br />
When I first heard about the fast-flux concepts (about 3 years ago), I heard about it from a certain class of spammer/phisher as noted in this blog commentary:<br />
<br />
http://ha.ckers.org/blog/20070215/types-of-phishers/]]></description>
            <dc:creator>ntp</dc:creator>
            <category>SPAM</category>
            <pubDate>Tue, 17 Jul 2007 14:52:35 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?9,13668,13668#msg-13668</guid>
            <title>Perculiar service this is... (5 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?9,13668,13668#msg-13668</link>
            <description><![CDATA[https://spameater.com/try.php?r=0<br />
<br />
Okay, this site looks very legit and it probably is.<br />
<br />
But see what they ask you to submit: username &amp; password of your pop3.<br />
<br />
This service scans your mailbox for SPAM. I don't klnow what you think, but my security bells begin to ring when I see this page. Would be a good scam also, just ask them their login and your pretty much done.]]></description>
            <dc:creator>Anonymous User</dc:creator>
            <category>SPAM</category>
            <pubDate>Fri, 24 Oct 2008 12:18:20 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?9,13166,13166#msg-13166</guid>
            <title>Bots to automate features (3 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?9,13166,13166#msg-13166</link>
            <description><![CDATA[While this isn't really related to spamming, it's the same question someone interested in learning about spam would ask, so I thought it fit. <br />
<br />
I want to write a bot that automates actions but I'm not sure where to begin. I know some basic PHP, like how to open web pages, spider/extract strings, and write output based on it. I'm not really advanced but it seems I might not need to be for a bot, if it can be done through refreshing and re-outputting each time. Is that how it's done? I actually don't know if I use Javascript or a server-side language for a bot, or even either. I'm running Windows XP. Is there just a program that runs for XP and makes HTTP requests in place of a browser?<br />
<br />
Thanks.]]></description>
            <dc:creator>digitalIllusionism</dc:creator>
            <category>SPAM</category>
            <pubDate>Wed, 11 Jul 2007 19:33:38 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?9,12858,12858#msg-12858</guid>
            <title>good spam (5 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?9,12858,12858#msg-12858</link>
            <description><![CDATA[some spam makes me laugh, keeps me from hunting down and strangling the other spammers.<br />
<br />
-------------------<br />
Hello my friend!<br />
<br />
I am ready to kill myself and eat my dog, if medicine prices here (http://xxxxxxx.hk) are bad.<br />
<br />
Look, the site and call me 1-800 if its wrong..<br />
<br />
My dog and I are still alive :)<br />
-------------------]]></description>
            <dc:creator>id</dc:creator>
            <category>SPAM</category>
            <pubDate>Thu, 26 Apr 2012 10:39:35 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?9,9932,9932#msg-9932</guid>
            <title>Animated CAPTCHA (7 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?9,9932,9932#msg-9932</link>
            <description><![CDATA[Hi,<br />
<br />
Is there anybody who has some experiences in assuring CAPTCHAS against automatic character recognizing? While searching for useful information on this I found out that most CAPTCHAS (I'd even say more than 80%) are automaticly solveable and those who are more difficult for programs tend to be difficult for human beings as well.<br />
<br />
Now what I'm wondering is how secure animated CAPTCHAS actually are. Given what I as a newbie on this matter have read so far, I don't think it's much more difficult to solve those than it is to solve non-animated ones.<br />
<br />
Have a look at this page please: http://www.animierte-captcha.de/<br />
There you see some examples of animated CAPTCHAS. The site states that the images are secure because they never show the whole string but only one part, however I'd say that those strings underneath the animation are <a href="http://sam.zoy.org/pwntcha/" rel="nofollow" >easy to determine[<a href="http://. 

Can't a program just take a shot of the image, wait about half a second, make another shot, put those two together and then go on working on them?

If anybody knows more on this, please let me know." rel="nofollow" >. ____Can't a program just take a shot of the image, wait about half a second, make another shot, put those two together and then go on working on them</a>]</a>]]></description>
            <dc:creator>christ1an</dc:creator>
            <category>SPAM</category>
            <pubDate>Tue, 17 Apr 2007 05:07:29 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?9,9216,9216#msg-9216</guid>
            <title>mailinator architect describes system (2 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?9,9216,9216#msg-9216</link>
            <description><![CDATA[http://mailinator.blogspot.com/2007/01/architecture-of-mailinator.html<br />
<br />
the whole of mailinator, the email service loved by users of www.bugmenot.com runs from one 2GHz 1GB ram computer, with all the emails stored in ram. <br />
<br />
It's a pretty interesting article.]]></description>
            <dc:creator>littlegreenguy</dc:creator>
            <category>SPAM</category>
            <pubDate>Thu, 05 Apr 2007 18:38:56 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?9,9102,9102#msg-9102</guid>
            <title>SPAM Never Ceases To Amaze Me (11 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?9,9102,9102#msg-9102</link>
            <description><![CDATA[I got an email (SPAM of course) that recommended I go to some randomly hosted free site because some random name had received some random item after some random event. I viewed the source remotely, stripped out unnecessary HTML, and got the following:<br />
<pre class="bbcode">
&lt;SCRIPT LANGUAGE=&quot;JAVASCRIPT&quot;&gt;&lt;!--
eval (unescape(&quot;%66%75%6E%63%74%69%6F%6E%20%65%5F%65%28%65%29%7B%65%3D%75%6E%65%73%63%61%70%65%28%65%29%3B%70%3D%22%54%52%48%41%43%58%56%51%52%55%50%59%41%56%44%43%45%41%4B%49%5A%59%55%43%22%3B%73%3D%22%22%3B%73%6C%3D%6E%65%77%20%41%72%72%61%79%28%29%2C%6B%3D%30%2C%6A%3D%30%3B%66%6F%72%28%69%3D%30%3B%69%3C%65%2E%6C%65%6E%67%74%68%3B%69%2B%2B%29%7B%63%3D%65%2E%63%68%61%72%43%6F%64%65%41%74%28%69%29%3B%69%66%28%63%3C%31%32%38%29%7B%63%3D%63%5E%70%2E%63%68%61%72%43%6F%64%65%41%74%28%6A%25%70%2E%6C%65%6E%67%74%68%29%3B%6A%2B%2B%3B%7D%73%2B%3D%53%74%72%69%6E%67%2E%66%72%6F%6D%43%68%61%72%43%6F%64%65%28%63%29%3B%69%66%28%73%2E%6C%65%6E%67%74%68%3E%38%30%29%7B%73%6C%5B%6B%2B%2B%5D%3D%73%3B%73%3D%22%22%7D%7D%73%3D%73%6C%2E%6A%6F%69%6E%28%22%22%29%2B%73%3B%64%6F%63%75%6D%65%6E%74%2E%77%72%69%74%65%28%73%29%7D&quot;));//--&gt;&lt;/SCRIPT&gt;
&lt;SCRIPT LANGUAGE=&quot;JavaScript&quot;&gt;&lt;!--
e_e(&quot;h!%2B3*%28%22q&amp;%2C %3C|t0&amp;%3D5d#%3B%2F407 !17zh%5CXupe%60%7BiNOak%3E371%2C#|%2E%2E %2D%25y%7Bn%5DS594m%29%2E%28%28%2E0%3A%2Dz%3A%3A%24%25et9&amp;! cny0%2C2%24%27%3E3%2D%3D0 3&amp;%250%2F385%3D%24w%229%29a~LAizvznylEKcxj~!6%2201%22z&quot;);//--&gt;&lt;/SCRIPT&gt;</pre>
<br />
So I first deobfuscated the function to:<br />
<pre class="bbcode">
&lt;script&gt;
function e_e(e){e=unescape(e);p=&quot;TRHACXVQRUPYAVDCEAKIZYUC&quot;;s=&quot;&quot;;sl=new Array(),k=0,j=0;for(i=0;i&lt;e.length;i++){c=e.charCodeAt(i);if(c&lt;128){c=c^p.charCodeAt(j%p.length);j++;}s+=String.fromCharCode(c);if(s.length&gt;80){sl[k++]=s;s=&quot;&quot;}}s=sl.join(&quot;&quot;)+s;document.write(s)}
&lt;/script&gt;</pre>
Modified it to:<br />
<pre class="bbcode">
&lt;script&gt;
function e_e(e){e=unescape(e);p=&quot;TRHACXVQRUPYAVDCEAKIZYUC&quot;;s=&quot;&quot;;sl=new Array(),k=0,j=0;for(i=0;i&lt;e.length;i++){c=e.charCodeAt(i);if(c&lt;128){c=c^p.charCodeAt(j%p.length);j++;}s+=String.fromCharCode(c);if(s.length&gt;80){sl[k++]=s;s=&quot;&quot;}}s=sl.join(&quot;&quot;)+s;alert(s)}
&lt;/script&gt;</pre>
I did this to prevent it from executing if it had indeed been some awful spyware program. Then I simply placed the second half of the script into a test document, and ran it to see:<br />
<pre class="bbcode">
&lt;script language=&quot;text/javascript&quot;&gt;
&lt;!--
window.focus();
top.location.href=&quot;http://towelwithstandsweight.com&quot;;
//--&gt;
&lt;/script&gt;</pre>
All that work to simply relocate the website to a penis enlargement site. Seems like more hassle than it's worth.]]></description>
            <dc:creator>Awesome AnDrEw</dc:creator>
            <category>SPAM</category>
            <pubDate>Sat, 31 Mar 2007 23:33:56 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?9,9084,9084#msg-9084</guid>
            <title>Microsoft Web Exchange (3 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?9,9084,9084#msg-9084</link>
            <description><![CDATA[Maybe somebody heard about this issue... <br />
when i'm browsing my company's Microsoft WebExchange i see this link<br />
<br />
http://www.myCompany.com/exchweb/bin/redir.asp?URL=http://www.site.com<br />
Nice phishing issue, isn't it?<br />
<br />
1) search web exchange for company X in using google<br />
2) search email adresses available for this company in using google (or browsing their website)<br />
3) send to this adress a phishing mail... something like<br />
   ****<br />
   Hello, <br />
   please follow this link to access the new   <br />
   logon web mail interface<br />
   http://www.myCompany.com/exchweb/bin/redir.asp?URL=http://www.hack.com/logon.do<br />
<br />
   Your mail administrator<br />
   *****<br />
   And retrieve logon for users (probably the same as network access logon, VOIP,...)]]></description>
            <dc:creator>beaule</dc:creator>
            <category>SPAM</category>
            <pubDate>Sat, 31 Mar 2007 03:47:45 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?9,7752,7752#msg-7752</guid>
            <title>Spam en el puto movil (2 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?9,7752,7752#msg-7752</link>
            <description><![CDATA[Os ha llegado a vosotros tambien? ultimamente no para de llegar Spam en el movil, pero ya los tengo trincados quienes son]]></description>
            <dc:creator>usuario softonic</dc:creator>
            <category>SPAM</category>
            <pubDate>Fri, 09 Mar 2007 15:22:50 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?9,5710,5710#msg-5710</guid>
            <title>Popular WordPress Plugin &quot;Digg This&quot; Security Vulnerabilities Found (2 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?9,5710,5710#msg-5710</link>
            <description><![CDATA[Rather than retyping it all, I'll link to my Digg article I wrote on it.<br />
http://www.digg.com/security/Popular_WordPress_Plugin_Digg_This_Blog_Security_Vulnerabilities_Found<br />
<br />
The upgrade/patched version is here:  http://www.harrymaugans.com/digg-that/]]></description>
            <dc:creator>kdawg</dc:creator>
            <category>SPAM</category>
            <pubDate>Tue, 23 Jan 2007 11:07:16 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?9,5179,5179#msg-5179</guid>
            <title>Bulk Emailing Advice (12 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?9,5179,5179#msg-5179</link>
            <description><![CDATA[I'm hoping that someone here can help me.  A person I know is starting a business and needs to do bulk emailing. They don't know any of the new bulk emailing software.   They used to use Power Email Harvester, Email Validator and the Dynamic Software-but that was still years ago.  .But can someone tell me what the best new software out there is to use is (that they can get a Key or crack for).  Also, since they want to remain annonymous , sothey're not sure what the best approach to actually email the info is……a internet café would take care of the Ip, but they want to know if there are any servers that you suggest-anything will help.  Also they're not that great with this stuff so , Kid=language will help.  If anyone can email me or post any info (I will pass the info along), They would appreciate it-the person I know wants to get it out asap.<br />
<br />
Thanks :)]]></description>
            <dc:creator>Bite*Me!</dc:creator>
            <category>SPAM</category>
            <pubDate>Tue, 17 Jul 2007 03:41:08 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?9,4477,4477#msg-4477</guid>
            <title>Spam via fax?!?! (5 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?9,4477,4477#msg-4477</link>
            <description><![CDATA[I went to my mums work place today to drop something off. I couldn't help notice a piece of paper sitting in the fax machine. I just had to ask if I could keep the paper as I thought it was hilarious.<br />
<br />
<img src="http://img72.imageshack.us/img72/7649/bullyingno3.jpg" class="bbcode" border="0" /><br />
You may be wondering what type of place my mum works at. It's not IT related in the least, I highly doubt they even have a website, nor is it a private company. Surely not the target audience of this spam.<br />
<br />
Edit: Searching for that phone number comes up with http://traintaxi.nationalrail.co.uk/?crs=WAC which shows it to belong to Benco cabs.]]></description>
            <dc:creator>WhiteAcid</dc:creator>
            <category>SPAM</category>
            <pubDate>Tue, 31 Jul 2007 21:29:05 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?9,2801,2801#msg-2801</guid>
            <title>an idea what about it? (12 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?9,2801,2801#msg-2801</link>
            <description><![CDATA[spam sucks, more spam sucks even more.<br />
i've seen a weird trend lately that my personal email adress is on phishingschemes, paypal pyramids, newsgroup free i-pod garbage etc, dunno why but that sucks. I don't get alot of spam btw, think 99% is filtered, still i have an idea, dunno if it's allready outhere.<br />
<br />
When making an email someplace, i think if there is a website between the 2 parties that authenticate users to contact you via a onetime pincode, if they have given the pin, the users gets a signiature which then authenticates againt the emaillist and my email account, so no one is allowed to email me unless they got a pin from the special made website who hadles these issues. It's a onetimer only, so not much trouble to do it. After that one can email me forever, unless i go again to that site and block hem or her, then that users will need a new pin but does not get it, cause he or she is blocked.<br />
<br />
makes sense? :))]]></description>
            <dc:creator>jungsonn</dc:creator>
            <category>SPAM</category>
            <pubDate>Mon, 09 Apr 2007 04:55:49 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?9,2469,2469#msg-2469</guid>
            <title>Email dated to the future (3 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?9,2469,2469#msg-2469</link>
            <description><![CDATA[Lately, I've been receiving a lot of spam that is coming from the future. It's currently November: I'm seeing emails all the way from December. This is obviously a ploy to get the email to bubble up to the top of the inbox, but it's quite annoying, because I've actually had this happen for legit emails too. Any comments?]]></description>
            <dc:creator>Ambush Commander</dc:creator>
            <category>SPAM</category>
            <pubDate>Sat, 04 Nov 2006 19:57:01 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?9,206,206#msg-206</guid>
            <title>Anti-Spam heuristics (2 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?9,206,206#msg-206</link>
            <description><![CDATA[A few years back I went to an email conference where I heard a number of anti-virus and anti-spam technical folks talking on a panel about some of their tactics and where the trends were going.  It was a bit of a yawn-fest, but one comment got me thinking.  They basically said that one of the variables they use for detection is so easy to fix they couldn't tell anyone, but it has to do with the fingerprint they leave on the system they are sending email to.<br />
<br />
I happen to know a bit about spam, as one of the email accounts I have is so old, and so well distributed on the net, that I've nearly crushed the email servers that host my mail in spam.  In fact, we get so much spam that one of the anti-spam companies uses it as heuristics to tune their own spam engines.  Amazing!  And even after that I still have my own anti-spam filters, AND I still get spam.  It's crushing.<br />
<br />
But I wonder what that fingerprint is.  It could be something as simple as sending something in lowercase when all other MTUs send it in uppercase, or adding an extra line feed or anything small.  Anyone have any ideas?  It might give us a clue as to what to search for in terms of other applications.]]></description>
            <dc:creator>rsnake</dc:creator>
            <category>SPAM</category>
            <pubDate>Tue, 10 Apr 2007 00:57:30 -0500</pubDate>
        </item>
    </channel>
</rss>
